Data processing addendum
Last updated:
This data processing addendum (“DPA”) applies when your organisation uses Rentap. It sets out how E2SOFT LTD processes personal data on your behalf, as required by Article 28 of the UK GDPR. It forms part of our terms of service and applies automatically, without signature, from the moment you use the service and for as long as we process personal data for you.
1. Parties and roles
Rentap is a product of E2SOFT LTD, a company registered in England and Wales (company number 11644732). Registered office: Unit Da2 Sutherland House, 43 Sutherland Road, London E17 6BU.
Email: hello@rentap.app
- You, the organisation that holds the Rentap account, are the controller of the personal data you and your users put into the app.
- We, E2SOFT LTD, are your processor for that data.
- For your account and billing details, website visits, messages to us and our server logs, we are the controller; our privacy notice covers that data, not this DPA.
Words such as “controller”, “processor”, “personal data”, “processing”, “data subject” and “personal data breach” have the meanings given in the UK GDPR and the Data Protection Act 2018 (together, “data protection law”).
2. Details of the processing
| Subject matter | Providing Rentap, software for managing houses let room by room in England, to you. |
|---|---|
| Duration | For as long as you use the service, and afterwards until the data is deleted as described in section 10. |
| Nature and purpose | Storing, organising, displaying, retrieving, sending (for example notifications and invitations), exporting and deleting your records, so that you and the people you invite can use the service. We process the data only to provide the service to you. |
| Types of personal data | Contact details (such as names, email addresses, phone numbers and addresses); tenancy and rent details; payment records; documents you upload; issue reports and messages; safety-check records; and sign-in details of the people you invite. The service does not need special category data (such as health information); please do not upload it unless it is necessary for your purposes. |
| Categories of data subjects | Your tenants and residents; guarantors, if you record them; your staff and other users you invite; and contractors and other people you pay or record. |
3. Processing only on your instructions
We process the personal data only on your documented instructions. These terms, your use of the app’s features and its settings, and any written instructions from your account owner are your instructions. This includes any transfer of the data outside the UK, which we make only as set out in section 9, unless the law requires otherwise; in that case we will tell you before processing, unless the law forbids it.
We never use your data for our own purposes: never for marketing, never sold, never shared with advertisers, never used to profile your tenants and never used to train AI models. If we think an instruction breaks data protection law, we will tell you straight away.
4. Confidentiality
Only E2SOFT LTD staff who need access to provide, support or secure the service can access your data, and they are bound by a duty of confidentiality.
5. Security (Article 32)
We take appropriate technical and organisational measures to protect your data, including:
- HTTPS (TLS) encryption for all traffic to the website, the app and our servers;
- each organisation’s data kept separate in the database with row-level security, so one organisation can never see another’s data;
- passwords stored only as one-way hashes, and optional two-step sign-in with an authenticator app;
- encrypted storage;
- access to production systems limited to E2SOFT LTD staff who need it, using SSH keys;
- nightly backups, kept for 7 days.
We review these measures as the service and the risks change.
6. Sub-processors
You give us general authorisation to use sub-processors. Our current sub-processors are:
| Provider | What they do for us | Where |
|---|---|---|
| Oracle Cloud Infrastructure (Oracle Corporation UK Ltd) | Hosting: the servers, database, file storage and backups that run the website and the app. Storage volumes are encrypted at rest. | UK South (London) region |
| Brevo (Sendinblue SAS) | Sending service emails: sign-in links, password resets, notifications and invitations. | France (EU) |
| Cloudflare, Inc. | DNS for our domain, and forwarding emails sent to @rentap.app addresses to our mailboxes. It does not sit in front of the website or the app. | Global network; may process outside the UK |
| Google (Google Maps Platform) | Address search when you add a property: the postcode or the part of the address you type is sent to find matching addresses. No names or other personal data are sent. | Global network; may process outside the UK |
| postcodes.io | Back-up postcode lookup when the address search above is unavailable. Only the postcode is sent; no other personal data. | Public postcode service; only the postcode leaves our servers |
Card payments are not switched on yet. The card payment provider will be added to this list before they are, and customers will be told in advance.
- We will tell you by email at least 30 days before we add or replace a sub-processor. If you object, you can close your account before the change takes effect.
- We put a written contract in place with each sub-processor that gives your data the same level of protection as this DPA.
- We remain responsible to you for the work of our sub-processors.
7. Helping you with data subject requests
Taking into account the nature of the processing, we help you respond to requests from people exercising their rights (access, rectification, erasure, restriction, portability and objection). You can view and correct most records yourself in the app, and the account owner can download an export. If a data subject contacts us directly about data you control, we will pass the request to you without undue delay and will not respond to it ourselves unless you ask us to.
8. Breaches, impact assessments and consultation (Articles 32–36)
- Security: we help you meet your own security obligations through the measures in section 5.
- Breach notification: we will tell you without undue delay, and within 48 hours of becoming aware of it, about a personal data breach affecting your data. We will give you the information we have about what happened, the data and people likely to be affected, its likely consequences and what we are doing about it, and keep you updated, so that you can meet your own duty to report to the ICO and tell the people affected.
- Impact assessments and prior consultation: we will give you reasonable help, using information available to us, with data protection impact assessments and with any prior consultation with the ICO.
9. International transfers
Your data is hosted in the UK. Brevo processes service emails in the European Union, covered by the UK adequacy regulations. Cloudflare and Google may process data outside the UK, protected by the UK Extension to the EU-US Data Privacy Framework and/or the UK International Data Transfer Addendum. We will not make other transfers outside the UK without appropriate safeguards under data protection law.
10. Deletion or return at the end
Before you close your account, the account owner can download an export of all your records. After your account is closed, we delete your organisation’s data from the app within 90 days, and the backups that contain it are overwritten within 7 more days. If you need a copy after closing, ask us within that period and we will provide it. We keep data longer only if the law requires us to.
11. Information and audits
We will make available to you the information you reasonably need to show that we meet our obligations under Article 28, and will allow and contribute to audits, including inspections, by you or an auditor you appoint. Audits must be on reasonable written notice, at your cost, not more than once a year unless there has been a personal data breach affecting your data, and subject to confidentiality and to the security of other customers’ data.
12. General
- This DPA forms part of the terms of service. If they conflict about personal data you control, this DPA wins.
- The limits of liability in the terms of service apply to this DPA, as far as the law allows.
- We may update this DPA, for example to add a sub-processor or reflect a change in the law, by giving notice as described in the terms of service. We will not reduce the protection it gives your data.
- This DPA is governed by the law of England and Wales.
Questions about this DPA: hello@rentap.app.